Skip to content

Bump cyclonedx-core-java and json-schema-validtor libs - #6515

Merged
nscuro merged 1 commit into
DependencyTrack:mainfrom
nscuro:bump-json-schema-validator-and-cyclonedx
Jun 25, 2026
Merged

Bump cyclonedx-core-java and json-schema-validtor libs#6515
nscuro merged 1 commit into
DependencyTrack:mainfrom
nscuro:bump-json-schema-validator-and-cyclonedx

Conversation

@nscuro

@nscuro nscuro commented Jun 25, 2026

Copy link
Copy Markdown
Member

Description

Bumps cyclonedx-core-java to 12.2.0 and json-schema-validator to 2.0.3 (the latter was blocking the former).

Addresses a variety of breaking changes in json-schema-validator, among them:

  • Renaming and relocation of classes
  • Changes in default error message content

Additionally, moves the schema validation logic entirely into our own CycloneDxValidator instead of delegating to cyclonedx-core-java. The reason for this is that I noticed during testing that cyclonedx-core-java does not cache schemas after first use, so every validation call would reload schemas from disk, and recompile them, which is just wasted work.

Addressed Issue

N/A

Additional Details

Supersedes

Checklist

  • I have read and understand the contributing guidelines
  • This PR fixes a defect, and I have provided tests to verify that the fix is effective
  • This PR implements an enhancement, and I have provided tests to verify that it works as intended
  • This PR introduces changes to the database model, and I have updated the migration changelog accordingly
  • This PR introduces new or alters existing behavior, and I have updated the documentation accordingly
  • This PR is a substantial change (per the ADR criteria), and I have added an ADR under docs/adr/

Bumps cyclonedx-core-java to 12.2.0 and json-schema-validator to 2.0.3 (the latter was blocking the former).

Addresses a variety of breaking changes in json-schema-validator, among them:

* Renaming and relocation of classes
* Changes in default error message content

Additionally, moves the schema validation logic entirely into our own `CycloneDxValidator` instead of delegating to cyclonedx-core-java. The reason for this is that I noticed during testing that cyclonedx-core-java does not cache schemas after first use, so every validation call would reload schemas from disk, and recompile them, which is just wasted work.

Signed-off-by: nscuro <nscuro@protonmail.com>
@nscuro nscuro added this to the 5.1 milestone Jun 25, 2026
@nscuro nscuro added the enhancement New feature or request label Jun 25, 2026
@owasp-dt-bot

Copy link
Copy Markdown

Snyk checks have passed. No issues have been found so far.

Status Scan Engine Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@codacy-production

codacy-production Bot commented Jun 25, 2026

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 1 critical

Results:
1 new issue

Category Results
Security 1 critical

View in Codacy

🟢 Metrics 0 complexity · -2 duplication

Metric Results
Complexity 0
Duplication -2

View in Codacy

🟢 Coverage 86.17% diff coverage

Metric Results
Coverage variation Report missing for ec3a6941
Diff coverage 86.17% diff coverage (70.00%)

View coverage diff in Codacy

Coverage variation details
Coverable lines Covered lines Coverage
Common ancestor commit (ec3a694) Report Missing Report Missing Report Missing
Head commit (263fd95) 42349 36740 86.76%

Coverage variation is the difference between the coverage for the head and common ancestor commits of the pull request branch: <coverage of head commit> - <coverage of common ancestor commit>

Diff coverage details
Coverable lines Covered lines Diff coverage
Pull request (#6515) 94 81 86.17%

Diff coverage is the percentage of lines that are covered by tests out of the coverable lines that the pull request added or modified: <covered lines added or modified>/<coverable lines added or modified> * 100%

1 Codacy didn't receive coverage data for the commit, or there was an error processing the received data. Check your integration for errors and validate that your coverage setup is correct.

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

@nscuro
nscuro merged commit 1abb7f6 into DependencyTrack:main Jun 25, 2026
17 checks passed
@nscuro
nscuro deleted the bump-json-schema-validator-and-cyclonedx branch June 25, 2026 15:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants